Workspace Migration Services

Reference

Google Workspace security checklist

A Google Workspace security checklist should start with the 4 controls that close the most common breach paths: enforced 2-step verification, restricted third-party app access, external sharing limits on Drive, and an alert on super admin role changes. Everything else is refinement on top of those.

Controls in risk order
1. 2-step verificationEnforced for all users, security keys for admins
2. Third-party app accessMove from unrestricted to allow-listed OAuth scopes
3. External Drive sharingWarn or restrict outside the domain, disable link-anyone by default
4. Super admin alertsAlert centre rule on role grant, plus fewer than 4 super admins
5. Email authenticationSPF, DKIM and DMARC at enforcement, not p=none
6. Recovery pathsAdmin recovery contacts verified and less privileged accounts for daily use

Why the order matters more than the list

Checklists fail because they are worked alphabetically. The account takeover route in nearly every incident we see is a password reused elsewhere plus an OAuth grant to a tool nobody reviewed, so those two items belong first regardless of how many other settings are open.

Working in risk order also means an admin who runs out of time on a Friday has still closed the expensive paths rather than the cosmetic ones.

The controls people skip

Super admin count is the one most often ignored. Tenants of sixty seats routinely carry six or seven super admins, several belonging to former contractors, and each is a full-tenant compromise waiting for one phishing click.

The second is alerting. Settings without alerts are a snapshot; a rule that emails on role change or on suspicious login turns the configuration into something you notice being undone.

  • Cap super admins and give day-to-day work a delegated role
  • Enable alert centre rules for role grants and suspicious sign-ins
  • Review OAuth grants quarterly rather than at incident time
  • Turn off IMAP and POP where nobody uses them
  • Check that every admin has a verified recovery method

What we see that others don't say

Across the Workspace tenants we assess, unreviewed third-party OAuth grants outnumber disabled 2-step verification accounts, yet almost no checklist places app access above password policy.

What this doesn't cover

  • This checklist covers Workspace tenant configuration, not endpoint security, network controls or the applications outside Workspace.
  • Some controls listed require Business Plus or Enterprise; the checklist notes the risk, not the licence you hold.

Want this done for you?

Three fields. We come back with whether this is a 20-minute fix or a project, and what it costs.

Prefer to talk? Call +44 20 7183 3436 (Mon–Fri 08:00–18:00 GMT), or message WhatsApp +44 7403 423563.

Questions we get asked

How many super admins should a Google Workspace tenant have?
Fewer than four for most organisations, with two as a working minimum so nobody is locked out. Daily administration should run through delegated roles rather than super admin accounts.
What is the single highest-value Workspace security change?
Enforced 2-step verification for every user, with hardware security keys on admin accounts. It removes the credential-reuse path that begins most of the account compromises we are called to investigate.

How this page is verified

Reviewed by Workspace Migration Services security desk, Workspace security and compliance reviewers. Last checked .

  • Control names and console locations verified against Google's security checklist documentation at the review date.
  • Ordering drawn from the initial access paths recorded in our own incident work.

Sources you can check

Related pages

Want the checklist run against your tenant?

A security review works these controls in order, records the current state of each with evidence, and returns a change list your admin can apply in an afternoon.